Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My browser had this down as a phising site? The actual content seems fine though.


Author here. This is strange, as I only use the Ghost site itself for hosting. I don't do any self-hosting or anything. Until this week, I'd never heard of anyone having troubles, but over on Reddit I saw a long-time reader getting some kind of SSL error, then later it said the site "wasn't available". Now in that thread someone else is getting that "phishing" error.

Time to get ahold of Ghost tech support and see what's going on. Sorry for the troubles!


The SSL error is likely from visitors on networks that use network-level blocking of domains that have been flagged as malicious. When visiting such a site over unencrypted HTTP you get redirected to an error page that explains the problem, but of course the network can't do this over HTTPS (by design), so you instead just get an opaque protocol error. (The specifics of the error message actually lead me to suspect that they might just be shoving the HTTP error-page response into the HTTPS connection, never mind that it's the wrong protocol.)

It's possible that putting your site behind Cloudflare and enabling Encrypted Client Hello might fix this, though I haven't tested it.


The site is fine. Doesn't show up as anything bad on Firefox on Mac. I've been reading the site for months, never had a problem.


Same here (Firefox on Windows). But when I opened it in Firefox on my Android phone, it seems fine.


Confirm via uBo. Didn't bother with content because of that.


Actually parts of the content aren't loading, probably also due to it being listed? Strange though! I wonder what happened?



Interesting, the source is (a subdomain on) the Ghost blogging platform.


Author here. Yes, I don't self-host exactly because I was hoping to avoid stuff like this by relying on a more robust back-end than I could provide.


Unfortunately even a managed host like Ghost doesn't have much ability to help you with this particular problem; your particular site is treated as its own separate thing in malicious-site databases. (Since, after all, there's nothing stopping a bad guy from hosting a phishing site on a ghost.io subdomain.)


Author here and... what the heck?!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: